CVE-2026-107839
Received Received - Intake

ageLANServer Memory Exhaustion via Unbounded JSON Array

Vulnerability report for CVE-2026-107839, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no request body size limit or cap on the attacker-controlled JSON names array and allocates response storage directly from the unbounded array length. A remote unauthenticated client can use the default self-registration flow and send an oversized request that causes excessive memory allocation, crashes or hangs the server process, disconnects active players, and keeps the service unavailable until it is restarted. This issue is fixed in version 1.15.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
luskaner ageLANServer < 1.15.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ageLANServer is a web server and launcher for offline multiplayer in Age of Empires and Age of Mythology games. The vulnerability exists in the AoE3 POST /game/cloud/getFileURL handler before version 1.15.2. It allows a remote unauthenticated attacker to send a request with an excessively large JSON names array. The server allocates memory based on this array length without any size limits, causing excessive memory consumption. This leads to crashes, hangs, or service unavailability until the server is restarted.

Detection Guidance

This vulnerability can be detected by monitoring for excessive memory usage or crashes in the ageLANServer process, particularly when handling POST requests to /game/cloud/getFileURL. Check server logs for unusually large JSON arrays in requests or responses. Use system monitoring tools like 'top', 'htop', or 'ps' to observe memory consumption spikes during network activity.

Impact Analysis

If you run an ageLANServer instance prior to version 1.15.2, an attacker could exploit this to crash the server, disconnect active players, and keep the service unavailable. This disrupts multiplayer gaming sessions and requires manual server restart to restore functionality.

Compliance Impact

This vulnerability primarily causes denial of service by crashing or hanging the server, which disrupts service availability. While it does not directly expose or leak data, prolonged unavailability could impact systems handling regulated data. GDPR requires ensuring availability of processing systems, and HIPAA requires safeguards against disruptions that could affect data integrity or access. However, this specific issue is more about service disruption than data protection.

Mitigation Strategies

Immediately update ageLANServer to version 1.15.2 or later to patch the vulnerability. If updating is not immediately possible, restrict network access to the server or disable the affected endpoint if feasible. Monitor server performance closely for signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107839. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart